<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:38:16.401349+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-00103</id>
    <title>bdu:2018-00103</title>
    <updated>2026-10-03T04:38:16.428019+00:00</updated>
    <content>bdu:2018-00103</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-00103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2017-9798</id>
    <title>Withdrawn: BELL-CVE-2017-9798 — CVE-2017-9798 does not affect BellSoft software</title>
    <updated>2026-10-03T04:38:16.428064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2017-9798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2017-avi-336</id>
    <title>certfr-2017-avi-336 — Une vulnérabilité a été découverte dans Apache Httpd. Elle permet à un
attaquant de provoquer un problème de sécurité n…</title>
    <updated>2026-10-03T04:38:16.428083+00:00</updated>
    <content>certfr-2017-avi-336</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2017-avi-336"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-34171</id>
    <title>cnvd-2017-34171</title>
    <updated>2026-10-03T04:38:16.428099+00:00</updated>
    <content>cnvd-2017-34171</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-34171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258771</id>
    <title>EUVD-2026-258771</title>
    <updated>2026-10-03T04:38:16.428111+00:00</updated>
    <content>EUVD-2026-258771</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258771"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-9798</id>
    <title>fkie_cve-2017-9798</title>
    <updated>2026-10-03T04:38:16.428121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-9798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jxf6-fx3m-8x2r</id>
    <title>GHSA-jxf6-fx3m-8x2r</title>
    <updated>2026-10-03T04:38:16.428152+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jxf6-fx3m-8x2r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-9798</id>
    <title>gsd-2017-9798</title>
    <updated>2026-10-03T04:38:16.428171+00:00</updated>
    <content>gsd-2017-9798</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-9798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10623-1</id>
    <title>openSUSE-SU-2024:10623-1 — apache2-2.4.49-1.1 on GA media</title>
    <updated>2026-10-03T04:38:16.428183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache2-2.4.49-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10623-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:2972</id>
    <title>RHSA-2017:2972 — Red Hat Security Advisory: httpd security update</title>
    <updated>2026-10-03T04:38:16.428215+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>httpd: Use-after-free by limiting unregistered HTTP method (Optionsbleed) httpd: # character matches all IPs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:2972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2017:2542-1</id>
    <title>SUSE-SU-2017:2542-1 — Security update for apache2</title>
    <updated>2026-10-03T04:38:16.428232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apache2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2017:2542-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-9798</id>
    <title>UBUNTU-CVE-2017-9798</title>
    <updated>2026-10-03T04:38:16.428245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: apache2, Ubuntu:16.04:LTS: apache2</p>
<p>Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-9798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594</id>
    <title>WID-SEC-W-2023-1594 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:38:16.428270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, seine Privilegien auszuweiten, Daten zu manipulieren, nicht spezifizierte Auswirkungen zu verursachen und einen Cross-Site-Scripting-Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1594"/>
  </entry>
</feed>
